Package Health

charithar/oauth2-openid-connect-server

This release has strong transparency and engineering hygiene for a newly published package: it is MIT-licensed, includes a substantial README, changelog, tests, CI, and a coherent source tree, has no install-time scripts, is not deprecated or archived, and its repository matches the package. However, it is extremely immature: v0.1.0 is the sole release, the package is effectively new, repository popularity is zero, and there is no recorded commit activity over the last three months. The absence of security scanning, a security policy, and explicit workflow token permissions adds avoidable operational risk. It may be reasonable to evaluate or adopt with caution, but it lacks the release history and maintenance evidence expected for a security-sensitive OpenID Connect dependency.

Latest v0.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Charitha Ratnayaka

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^5.3
lcobucci/clock
Version ^3.0
psr/http-factory
Version ^1.1
psr/http-message
Version ^1.1 || ^2.0
league/oauth2-server
Version ^9.1

Weekly Downloads

Info

Last Published
7 days ago
Created
7 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform